US9760426B2

Detecting anomalous accounts using event logs

Summary by NHIP

Process Anomaly Detection System

The system detects anomalous processes by converting directory paths into integer sequences based on sub-directory character counts. It identifies threats when process names match within a two-character error margin and the matching sequence count exceeds a threshold.

Claim Score by NHIP

Read claim 5, the broadest

Abstract

The claimed subject matter includes techniques for detecting anomalous accounts. An example method includes receiving, via a processor, a list of monitored machines and event logs including logons for the list of monitored machines for a predetermined window of time. The example method also includes generating, via the processor, a baseline based on the event logs for the predetermined window of time. The example method also includes collecting, via the processor, daily logon events after the predetermined time and comparing the daily logon events to the baseline. The method further includes detecting, via the processor, an anomalous account based on a difference of logon events of the anomalous account from the baseline. The method also includes displaying, via the processor, the detected anomalous account.

US9760426B2, drawing sheet 1
Sheet 1 of 9

Term

Projected expiry 12 August 2035.

  1. Priority and filed
  2. Granted
  3. Today
  4. Projected expiry

9 claims: 2 independent, 7 dependent

  1. 1
    A system for anomalous process detection, comprising:a processor;and a memory device coupled to the processor, the memory device to store instructions that, when executed by the processor, cause the processor to: receive a plurality of event logs;filter the plurality of event logs based on detected process creations;receive a directory path and process name for each detected process creation;convert each directory path to a sequence of integers based on a character count for each sub-directory of the directory path;detect an anomalous process based on a threshold number of matching character counts and matching process names, the processor to match a process within an error of two characters to a process name on a list of process names;and display the detected anomalous process.
  2. 5
    Broadest claimClaim Score 51, average(NHIP)A method for anomalous process detection, the method comprising:receiving, via a processor, a plurality of event logs;filtering, via the processor, the plurality of event logs to detect process creations;receiving, via the processor, a directory path and process name for each detected process creation;converting, via the processor, each directory path to a sequence of integers based on character count;detecting, via the processor, an anomalous process based on a threshold number of matching character counts, wherein the processor matches a process within an error of two characters to a process name on a list of process names;and displaying, via the processor, the detected anomalous process.